Tags: xss 

Rating:

https://gitlab.com/gitlab-org/gitlab-ce/commit/c4bb0a116efb8d95dcf7edd92424795ea919660f

You can inject xss script into mermaid contents easily.

payload :
```
graph LR
B-->D()
```